{"id":"CVE-2019-3772","details":"Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.","aliases":["GHSA-wr5r-m8pc-85j9"],"modified":"2026-09-13T03:45:04.798549013Z","published":"2019-01-18T22:29:00.973Z","database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:16.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:17.0:*:*:*:*:*:*:*","cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"16.0"},{"last_affected":"16.0"},{"introduced":"17.0"},{"last_affected":"17.0"},{"introduced":"18.0"},{"last_affected":"18.0"}],"source":"CPE_STRING","vendor_product":"oracle:retail_customer_management_and_segmentation_foundation"}]},"references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106749"},{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2019-3772"},{"type":"FIX","url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/spring-projects/spring-integration","events":[{"introduced":"0"},{"last_affected":"b8738160f54e5f65e2fcfdef62c661993ee427d5"},{"introduced":"628db1e111b70fd89f8c3f43942c8e330d875eea"},{"last_affected":"84c4c771924f2aa2f2ed703f61b2a69f46e1283a"},{"introduced":"58fecda5dfd74b2dbf5a6cacc3e25edae779ee6f"},{"last_affected":"b047b8d9bb0da79765fe862927273aa6ccadb546"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"4.3.18"},{"introduced":"5.0.0"},{"last_affected":"5.0.10"},{"introduced":"5.1.0"},{"last_affected":"5.1.1"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:vmware:spring_integration:*:*:*:*:*:*:*:*"}}],"versions":["v5.1.1.RELEASE","v5.1.0.RELEASE","v5.1.0.RC2","v5.1.0.RC1","v5.1.0.M2","v5.1.0.M1","v5.0.3.RELEASE","v5.0.2.RELEASE","v5.0.1.RELEASE","v5.0.0.RELEASE","v5.0.0.RC1","v5.0.0.M7","v5.0.0.M6","v5.0.0.M5","v5.0.0.M4","v5.0.0.M3","v5.0.0.M2","v5.0.0.M1","v4.3.1.RELEASE","v4.3.0.RELEASE","v4.3.0.RC1","v4.3.0.M2","v4.3.0.M1","v4.2.2.RELEASE","v4.2.1.RELEASE","v4.2.0.RELEASE","v4.2.0.RC1","v4.2.0.M2","v4.2.0.M1","v4.1.2.RELEASE","v4.1.1.RELEASE","v4.1.0.RELEASE","v4.1.0.RC1","v4.1.0.M1","v4.0.2.RELEASE","v4.0.1.RELEASE","v4.0.0.RELEASE","v4.0.0.RC1","v4.0.0.M4","v4.0.0.M3","v4.0.0.M2","v3.0.0.M3","v3.0.0.M2","v3.0.0.M1","v2.2.1b.RELEASE","v2.2.0.RELEASE","v2.2.0.RC3","v2.2.0.RC2","v2.2.0.RC1","v2.2.0.M4","v2.2.0.M4.SPRINT3","v2.2.0.M4.SPRINT2","v2.2.0.M4.SPRINT1","v2.2.0.M3","v2.2.0.M3.SPRINT3","v2.2.0.M3.SPRINT2","v2.2.0.M3.SPRINT1","v2.2.0.M2","v2.2.0.M1","v2.1.1.RELEASE","v2.1.0.RELEASE","v2.1.0.RC2","v2.1.0.RC1","v2.1.0.M3","v2.1.0.M2","v2.1.0.M1","v2.0.5.RELEASE","v2.0.4.RELEASE","v2.0.3.RELEASE","v2.0.2.RELEASE","v2.0.1.RELEASE","v2.0.0.RELEASE","v2.0.0.RC2","v2.0.0.RC1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-3772.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}